Description
Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via CREATE ALIAS (pre-auth RCE).
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

Northstar (dromara/northstar) versions 9.1.1 and earlier improperly expose the embedded H2 database console. The authentication interceptor only protects the /northstar/ path, leaving the /h2-console endpoint unprotected. The H2 database defaults to the sa user with an empty password, allowing any network‑reachable attacker to reach the console without credentials and to execute arbitrary system commands via the CREATE ALIAS statement, which runs arbitrary Java code in the application context. This flaw provides immediate remote code execution with full system access, compromising confidentiality, integrity, and availability of the affected environment.

Affected Systems

The vulnerable product is Dromara Northstar quantitative trading platform, versions up to and including 9.1.1. Any deployment that has the H2 console enabled and is reachable over the network is susceptible, regardless of other application users or roles. The flaw is not limited to local hosts; any attacker able to reach the console endpoint can exploit it.

Risk and Exploitability

The vulnerability lacks a published CVSS or EPSS score in the provided data, but the exposed console with default credentials and the ability to run arbitrary commands through SQL create alias indicates a severity higher than medium. The attack can be carried out remotely over the network without prior authentication, so the risk is high. Although the vulnerability is not currently listed in the CISA KEV catalog, the absence of KPIs does not diminish the exploitation potential. An attacker can directly compromise the host running the Northstar instance, gaining full control, and the exploit requires only network access to the /h2-console endpoint.

Generated by OpenCVE AI on October 5, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict network access to the /h2-console endpoint by firewalling or placing the application behind a VPN so that only trusted hosts can reach it.
  • Disable or remove the H2 console feature if it is not required, or enable authentication for the console by configuring the application to require a non‑default password for the sa user.
  • Upgrade Northstar to a version newer than 9.1.1 once a vendor patch becomes available, or apply any vendor‑issued fix that enforces authentication on the H2 console.

Generated by OpenCVE AI on October 5, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated H2 Console Allows Pre‑Auth Remote Code Execution
Weaknesses CWE-287
CWE-94

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via CREATE ALIAS (pre-auth RCE).
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T14:10:16.149Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88391

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T15:17:22.697

Modified: 2026-10-05T15:17:22.697

Link: CVE-2026-88391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T15:30:20Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')